AgentsWeaver
Security & trust

How AgentsWeaver keeps autonomous AI safe to run

Every job runs in an isolated sandbox, egress is bound to a single metered path, cost is capped before it's spent, and every action leaves a replayable receipt. That's what turns "autonomous AI in production" from a risk into a routine.

AgentsWeaver keeps autonomous AI safe by running every job in an isolated, rootless container with no network path except a metering gateway, reserving and settling its cost against a hard margin floor, and producing a replayable receipt with a full spend and audit trail — so unbounded cost, uncontrolled network access, and missing accountability are each closed off by design.
The guarantees

Four things every job on AgentsWeaver gets, automatically

You don't configure these — they apply to every job, every time, regardless of what the agent is doing.

Isolation

Each job runs in its own sandboxed, rootless container. Jobs are isolated per tenant, so one customer's job can never see or touch another's.

Controlled egress

The agent's only path to the network is a metering gateway. Nothing bypasses it — behaviour and cost are bounded by the same chokepoint.

Auditability

Every job produces a replayable receipt. A spend ledger and saga records give a full, reconstructable trail of what ran and what it cost.

Cost safety

Cost is reserved before a job runs and settled after, against a hard pre-commit margin floor. No runaway jobs, no surprise bills.

Why this matters

The usual fears about autonomous AI, each answered

Running an AI agent unattended raises the same three worries every time. AgentsWeaver answers each one structurally, not with a policy or a promise.

"It could spend without limit"

Cost is reserved before the job starts and settled after against a hard margin floor — spend is bounded up front, not discovered after the fact.

"We'd have no audit trail"

Every job leaves a replayable receipt plus ledger and saga records — you can reconstruct exactly what ran and what it cost, after the fact.

"It could reach anywhere on the network"

The only egress path is the metering gateway. There is no side channel to bypass it, so network reach is bounded by construction.

What you don't have to worry about

No fleet, no runtime, no secrets to manage

Customers host no agent runtime or fleet — there's no attack surface on your side to patch or scale. Secrets are managed centrally, server-side, and are never exposed to the customer or the public site. You submit a job and receive a result and a receipt; the sandbox, the gateway, and the ledger are the mesh's problem, not yours.

See what is AgentsWeaver for the bigger picture, and how it works for exactly how a job moves from submission to receipt.

FAQ

Common questions

Can an agent's job affect other tenants' jobs?
No. Every job runs in its own sandboxed, rootless container, and jobs are isolated per tenant. There is no shared state between one job and another.
What stops an agent from running up an unexpected bill?
Cost is reserved before the job runs and settled after, against a hard pre-commit margin floor. A job can't silently run past its cost bound.
How do I know what an agent actually did?
Every job produces a replayable receipt, backed by a spend ledger and saga records — a full, reconstructable trail of what ran and what it cost.
Do I need to host or secure any agent infrastructure myself?
No. Customers host no agent runtime or fleet, so there's no attack surface to patch or scale on your side. Secrets are managed centrally and are never exposed to you or the public site.

See it in action

Walk through the job lifecycle, or check the FAQ for more detail.